Netskope Threat Labs

SERVER-WEBAPP Microsoft SharePoint EntityInstanceIdEncoder remote code execution attempt

IPS-NPA

1 SID: 55862

Detects an attempt to exploit CVE-2019-0604, a remote code execution flaw that can run code on the server in Microsoft SharePoint EntityInstanceIdEncoder. The flaw saw use in targeted exploitation of SharePoint servers.